Step-by-step integration guide for secure payment authentication
The /FIDO/Challenge endpoint uses JWTs like other Cruise endpoints, but with extra ReferenceId and ReturnURL claims, to let users enroll in Visa Payment Passkey.
The following payload contains the transaction details:
{
"jti": "6aba7353-1682-48c0-a56a-8053383d9830",
"iat": 1786880099,
"iss": "582e0a2033fadd1260f990f6",
"OrgUnitId": "582be9deda52932a946c45c4",
"ObjectifyPayload": true,
"ReturnUrl": "http:\/\/www.coldslither.com\/visa\/passkey\/return.php",
"ReferenceId": "87f635a1-287e-487d-aa8e-8085c2061f01"
}
This is the complete JWT token posted to the iframe:
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJqdGkiOiI2YWJhNzM1My0xNjgyLTQ4YzAtYTU2YS04MDUzMzgzZDk4MzAiLCJpYXQiOjE3ODY4ODAwOTksImlzcyI6IjU4MmUwYTIwMzNmYWRkMTI2MGY5OTBmNiIsIk9yZ1VuaXRJZCI6IjU4MmJlOWRlZGE1MjkzMmE5NDZjNDVjNCIsIk9iamVjdGlmeVBheWxvYWQiOnRydWUsIlJldHVyblVybCI6Imh0dHA6XC9cL3d3dy5jb2xkc2xpdGhlci5jb21cL3Zpc2FcL3Bhc3NrZXlcL3JldHVybi5waHAiLCJSZWZlcmVuY2VJZCI6Ijg3ZjYzNWExLTI4N2UtNDg3ZC1hYThlLTgwODVjMjA2MWYwMSJ9.rlKUFcIDMW8b77yD-0FOztTIkfTaVT8bgG1oSchf2_k